Busca de CVEs
389.943 resultadosCVE-2026-55544HIGHNextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and TamperingEPSS 0.3%CVE-2026-47130HIGHNextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data TamperingEPSS 0.3%CVE-2026-47129HIGHNextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accountsEPSS 0.4%CVE-2026-44508—CVE-2026-44508EPSS 0.3%CVE-2026-44507—CVE-2026-44507EPSS 0.1%CVE-2026-56623HIGHApache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on WindowsEPSS 0.6%CVE-2026-56624HIGHApache MINA SSHD: SSH certificate options lack validationsEPSS 0.3%CVE-2026-64650MEDIUMAI SDK Codex Harness Tool Relay Authorization BypassEPSS 0.2%CVE-2026-58624MEDIUMApache MINA SSHD: Remote execution of JGit commands can write files on the serverEPSS 0.6%CVE-2026-44509—CVE-2026-44509EPSS 0.1%CVE-2026-56452HIGHApache MINA SSHD: Path traversal in SCP file receptionEPSS 0.5%CVE-2026-64651MEDIUMAI SDK OpenCode Harness Tool Relay Authorization BypassEPSS 0.2%CVE-2026-55219MEDIUMPaymenter: Race condition in payWithCredit() enables credit double-spendEPSS 0.2%CVE-2026-47198HIGHPaymenter: URL parameter injection bypasses paid plan limits at checkoutEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2026-53595CRITICALFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLEPSS 0.6%CVE-2026-13381HIGHVSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and DeletionEPSS 0.2%CVE-2026-53594MEDIUMFreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted PathEPSS 0.5%CVE-2026-13380CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP ResponsesEPSS 0.2%CVE-2026-44585MEDIUMPaymenter: Broken object level authorization via service reference manipulation on ticket creationEPSS 0.3%